telegram-mini-app

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly includes payment and blockchain transaction APIs: it documents TON Connect integration and provides concrete code to send TON transactions via tonConnectUI.sendTransaction (including address and amount fields). It also shows Telegram payment usage (bot.replyWithInvoice with provider_token, currency, prices) and mentions "In-app payments" and "TON payments" as monetization options. These are specific, financial-execution capabilities (crypto wallet transactions and invoice/payment APIs), so it meets the Direct Financial Execution criterion.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 07:45 PM